CVE-2026-54411: Linux-Pam

Medium severity, CVSS 5.9. EPSS: 0.5% chance of exploitation in the next 30 days.

Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.

Affected products

  • Linux-Pam Linux-Pam: up to and including 1.7.2

Published 2026-06-14. Last modified 2026-08-10.